This Data Processing Addendum ("Addendum") supplements the BounceZero Data Processing Agreement ("Master DPA") and applies where the customer ("Data Fiduciary", "you") submits for verification email addresses relating to data principals in India. It sets out how BounceZero Ltd ("Processor", "we", "us") complies with the Digital Personal Data Protection Act, 2023 ("DPDP Act") when acting as a data processor on your behalf. In the event of any conflict, the more protective obligation prevails.
1. Introduction
This Addendum forms part of the Master DPA. The terms defined in the Master DPA apply to this Addendum unless stated otherwise. Under the DPDP Act, "data fiduciary" means you, "data processor" means BounceZero, and "data principal" means the individual to whom the personal data relates (DPDP Act Sec. 2(k), 2(j), 2(m)).
We process personal data on EU infrastructure (OVH, France). BounceZero does not maintain an establishment in India; this Addendum governs our processing of personal data of Indian data principals on your behalf.
2. Governing Law and Regulator
The processing described in this Addendum is governed, so far as the data principals are in India, by the DPDP Act and the rules made under it. The principal provisions of the Act came into force in May 2025, with the main penalty provisions scheduled to become enforceable in May 2027. The regulator is the Data Protection Board of India (DPBI), which will adjudicate and determine breaches under the Act. Penalties for non-compliance can reach up to ₹250 crore per instance (DPDP Act Sec. 33).
3. Role and Scope
For the email verification services described in the Master DPA, you act as the data fiduciary and we act as the data processor. The subject matter, nature, and purpose of the processing are the same as set out in Section 2 of the Master DPA: syntactic validation, DNS/MX lookup, SMTP probing, catch-all detection, deliverability scoring, and fraud/abuse checks of the email addresses you submit.
We process personal data only on your documented instructions and never for our own benefit, except where applicable law requires otherwise (DPDP Act Sec. 2(j)).
4. Data Principal Rights
We will assist you in responding to requests from data principals exercising their rights under the DPDP Act, including the rights to:
- Obtain information about the processing of their personal data (Sec. 11).
- Request correction and erasure of their personal data (Sec. 12).
- Grievance redressal in respect of the processing (Sec. 13).
- Nominate another individual to exercise their rights after their death or incapacity (Sec. 14).
If a data principal contacts us directly, we will forward the request to you without undue delay and comply with your reasonable instructions. You are responsible for the legal basis of the processing, including any notice and consent or legitimate use relied on under Secs. 6 and 7.
5. Breach Notification
We will notify you of any personal data breach affecting the personal data you submitted, without reasonable delay after becoming aware of it, consistent with the Master DPA. You, as the data fiduciary, are responsible for notifying the Data Protection Board of India and affected data principals as required under Sec. 8(6) and the applicable rules. We will provide the information needed to support your notification.
6. Cross-Border Transfers
Personal data of Indian data principals is processed on EU infrastructure. The DPDP Act permits the transfer of personal data to any jurisdiction except those specifically restricted by the government by notification. No such restriction currently prevents transfers to the EU. To the extent any transfer relies on contractual safeguards, we rely on the Standard Contractual Clauses set out in the Master DPA. A copy is available on request at [email protected].
7. Additional Obligations
- Notice and consent support: we will provide the information about our processing reasonably needed for you to deliver the notice and, where applicable, obtain the consent required under Sec. 6, and to support any legitimate use you rely on under Sec. 7.
- Children data: if you submit email addresses that you know relate to children, you confirm that verifiable parental consent has been obtained where the Act requires it (Sec. 9), and you will notify us of that status.
- Security safeguards: we maintain the technical and organisational measures set out in Section 5 of the Master DPA, consistent with the reasonable security safeguards expected under Sec. 8.
- Records: we maintain processing records that allow you to demonstrate compliance with your obligations as data fiduciary.
- Audit: we will co-operate with reasonable audits conducted by you or your authorised auditor, on reasonable prior written notice.
8. Contact
For enquiries about this Addendum or to exercise rights in respect of the processing described here, contact our Data Protection contact:
BounceZero Ltd66 Paul Street, London, EC2A 4NA, United Kingdom
Email: [email protected]
You may also refer to the Master DPA and its terms on sub-processors, security measures, retention, and liability at bouncezero.io/dpa.